Description
An authenticated SQL injection vulnerability has been identified in multiple PHP Jabbers scripts. Improper neutralization of input provided by an authenticated user into parameters responsible for sorting functions allows an attacker to perform SQL Injection attacks.
This issue was fixed in the versions specified in the affected products list.
Published: 2026-07-31
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An authenticated user can manipulate sorting parameters that are not properly escaped, enabling the execution of arbitrary SQL statements within the database. The flaw can lead to unauthorized data disclosure, modification, or deletion, compromising confidentiality, integrity, and availability of stored information. The weakness is a classic SQL injection (CWE‑89).

Affected Systems

The vulnerability affects all PHP Jabbers application scripts listed, including Appointment Scheduler, Auto Classifieds Script, Availability Booking Calendar, Bus Reservation System, Business Directory Script, Car Park Booking System, Car Rental Script, Cinema Booking System, Cleaning Business Software, Equipment Rental Script, Event Booking Calendar, Event Ticketing System, Food Delivery Script, Hotel Booking System, Job Listing Script, Limo Booking Software, Meeting Room Booking System, Member Directory Script, Member Login Script, PHP Event Calendar, PHP Newsletter Script, PHP Shopping Cart, Product Comparison Script, Property Listing Script, Rental Property Booking Calendar, Restaurant Booking System, Service Booking Script, Shuttle Booking Software, Taxi Booking Script, Ticket Support Script, Time Slots Booking Calendar, Travel Tours Script, Vacation Rental Script, and Yacht Listing Script. The affected product versions are not specified; the issue is reported to exist across the current releases until a fixed version is released by the vendor.

Risk and Exploitability

The CVSS score of 8.6 indicates high severity, and the EPSS score of less than 1% suggests that exploitation is currently rare. The vulnerability is not listed in CISA’s KEV catalog, which reduces the likelihood of known exploitation but it remains a critical flaw if an attacker gains authenticated access. Because the flaw requires an authenticated session, the attack vector is inferred to be an authorized user or compromise of credentials. If an attacker can log in, they can execute arbitrary SQL, leading to potential data exfiltration or manipulation. Prompt patching is therefore essential to mitigate the risk of a substantial data breach.

Generated by OpenCVE AI on August 2, 2026 at 04:16 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest vendor patch for the affected PHP Jabbers scripts that includes the SQL injection fix.
  • If a patch is not yet available, remove or disable the sorting functionality until the fix is released to eliminate the injection surface.
  • Implement robust input validation and parameterized queries in all sorting endpoints to enforce safe handling of user input (addressing CWE‑89).

Generated by OpenCVE AI on August 2, 2026 at 04:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 31 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 31 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
Description An authenticated SQL injection vulnerability has been identified in multiple PHP Jabbers scripts. Improper neutralization of input provided by an authenticated user into parameters responsible for sorting functions allows an attacker to perform SQL Injection attacks. This issue was fixed in the versions specified in the affected products list.
Title Authenticated SQL Injection in PHP Jabbers scripts
First Time appeared Php Jabbers
Php Jabbers appointment Scheduler
Php Jabbers auto Classifieds Script
Php Jabbers availability Booking Calendar
Php Jabbers availability Calendar
Php Jabbers bus Reservation System
Php Jabbers business Directory Script
Php Jabbers car Park Booking System
Php Jabbers car Rental Script
Php Jabbers cinema Booking System
Php Jabbers cleaning Business Software
Php Jabbers equipment Rental Script
Php Jabbers event Booking Calendar
Php Jabbers event Ticketing System
Php Jabbers food Delivery Script
Php Jabbers hotel Booking System
Php Jabbers job Listing Script
Php Jabbers limo Booking Software
Php Jabbers meeting Room Booking System
Php Jabbers member Directory Script
Php Jabbers member Login Script
Php Jabbers php Event Calendar
Php Jabbers php Newsletter Script
Php Jabbers php Shopping Cart
Php Jabbers product Comparison Script
Php Jabbers property Listing Script
Php Jabbers rental Property Booking Calendar
Php Jabbers restaurant Booking System
Php Jabbers service Booking Script
Php Jabbers shuttle Booking Software
Php Jabbers taxi Booking Script
Php Jabbers ticket Support Script
Php Jabbers time Slots Booking Calendar
Php Jabbers travel Tours Script
Php Jabbers vacation Rental Script
Php Jabbers yacht Listing Script
Weaknesses CWE-89
CPEs cpe:2.3:a:php_jabbers:appointment_scheduler:*:*:*:*:*:*:*:*
cpe:2.3:a:php_jabbers:auto_classifieds_script:*:*:*:*:*:*:*:*
cpe:2.3:a:php_jabbers:availability_booking_calendar:*:*:*:*:*:*:*:*
cpe:2.3:a:php_jabbers:availability_calendar:*:*:*:*:*:*:*:*
cpe:2.3:a:php_jabbers:bus_reservation_system:*:*:*:*:*:*:*:*
cpe:2.3:a:php_jabbers:business_directory_script:*:*:*:*:*:*:*:*
cpe:2.3:a:php_jabbers:car_park_booking_system:*:*:*:*:*:*:*:*
cpe:2.3:a:php_jabbers:car_rental_script:*:*:*:*:*:*:*:*
cpe:2.3:a:php_jabbers:cinema_booking_system:*:*:*:*:*:*:*:*
cpe:2.3:a:php_jabbers:cleaning_business_software:*:*:*:*:*:*:*:*
cpe:2.3:a:php_jabbers:equipment_rental_script:*:*:*:*:*:*:*:*
cpe:2.3:a:php_jabbers:event_booking_calendar:*:*:*:*:*:*:*:*
cpe:2.3:a:php_jabbers:event_ticketing_system:*:*:*:*:*:*:*:*
cpe:2.3:a:php_jabbers:food_delivery_script:*:*:*:*:*:*:*:*
cpe:2.3:a:php_jabbers:hotel_booking_system:*:*:*:*:*:*:*:*
cpe:2.3:a:php_jabbers:job_listing_script:*:*:*:*:*:*:*:*
cpe:2.3:a:php_jabbers:limo_booking_software:*:*:*:*:*:*:*:*
cpe:2.3:a:php_jabbers:meeting_room_booking_system:*:*:*:*:*:*:*:*
cpe:2.3:a:php_jabbers:member_directory_script:*:*:*:*:*:*:*:*
cpe:2.3:a:php_jabbers:member_login_script:*:*:*:*:*:*:*:*
cpe:2.3:a:php_jabbers:php_event_calendar:*:*:*:*:*:*:*:*
cpe:2.3:a:php_jabbers:php_newsletter_script:*:*:*:*:*:*:*:*
cpe:2.3:a:php_jabbers:php_shopping_cart:*:*:*:*:*:*:*:*
cpe:2.3:a:php_jabbers:product_comparison_script:*:*:*:*:*:*:*:*
cpe:2.3:a:php_jabbers:property_listing_script:*:*:*:*:*:*:*:*
cpe:2.3:a:php_jabbers:rental_property_booking_calendar:*:*:*:*:*:*:*:*
cpe:2.3:a:php_jabbers:restaurant_booking_system:*:*:*:*:*:*:*:*
cpe:2.3:a:php_jabbers:service_booking_script:*:*:*:*:*:*:*:*
cpe:2.3:a:php_jabbers:shuttle_booking_software:*:*:*:*:*:*:*:*
cpe:2.3:a:php_jabbers:taxi_booking_script:*:*:*:*:*:*:*:*
cpe:2.3:a:php_jabbers:ticket_support_script:*:*:*:*:*:*:*:*
cpe:2.3:a:php_jabbers:time_slots_booking_calendar:*:*:*:*:*:*:*:*
cpe:2.3:a:php_jabbers:travel_tours_script:*:*:*:*:*:*:*:*
cpe:2.3:a:php_jabbers:vacation_rental_script:*:*:*:*:*:*:*:*
cpe:2.3:a:php_jabbers:yacht_listing_script:*:*:*:*:*:*:*:*
Vendors & Products Php Jabbers
Php Jabbers appointment Scheduler
Php Jabbers auto Classifieds Script
Php Jabbers availability Booking Calendar
Php Jabbers availability Calendar
Php Jabbers bus Reservation System
Php Jabbers business Directory Script
Php Jabbers car Park Booking System
Php Jabbers car Rental Script
Php Jabbers cinema Booking System
Php Jabbers cleaning Business Software
Php Jabbers equipment Rental Script
Php Jabbers event Booking Calendar
Php Jabbers event Ticketing System
Php Jabbers food Delivery Script
Php Jabbers hotel Booking System
Php Jabbers job Listing Script
Php Jabbers limo Booking Software
Php Jabbers meeting Room Booking System
Php Jabbers member Directory Script
Php Jabbers member Login Script
Php Jabbers php Event Calendar
Php Jabbers php Newsletter Script
Php Jabbers php Shopping Cart
Php Jabbers product Comparison Script
Php Jabbers property Listing Script
Php Jabbers rental Property Booking Calendar
Php Jabbers restaurant Booking System
Php Jabbers service Booking Script
Php Jabbers shuttle Booking Software
Php Jabbers taxi Booking Script
Php Jabbers ticket Support Script
Php Jabbers time Slots Booking Calendar
Php Jabbers travel Tours Script
Php Jabbers vacation Rental Script
Php Jabbers yacht Listing Script
References
Metrics cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Php Jabbers Appointment Scheduler Auto Classifieds Script Availability Booking Calendar Availability Calendar Bus Reservation System Business Directory Script Car Park Booking System Car Rental Script Cinema Booking System Cleaning Business Software Equipment Rental Script Event Booking Calendar Event Ticketing System Food Delivery Script Hotel Booking System Job Listing Script Limo Booking Software Meeting Room Booking System Member Directory Script Member Login Script Php Event Calendar Php Newsletter Script Php Shopping Cart Product Comparison Script Property Listing Script Rental Property Booking Calendar Restaurant Booking System Service Booking Script Shuttle Booking Software Taxi Booking Script Ticket Support Script Time Slots Booking Calendar Travel Tours Script Vacation Rental Script Yacht Listing Script
cve-icon MITRE

Status: PUBLISHED

Assigner: CERT-PL

Published:

Updated: 2026-07-31T19:51:58.085Z

Reserved: 2025-12-09T19:10:43.240Z

Link: CVE-2025-67650

cve-icon Vulnrichment

Updated: 2026-07-31T19:51:53.949Z

cve-icon NVD

Status : Received

Published: 2026-07-31T12:16:48.250

Modified: 2026-07-31T20:16:45.683

Link: CVE-2025-67650

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T04:30:13Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')